International Monetary Fund email accounts hacked in cyberattack

  • March 15, 2024
  •  
  • 03:48 PM
  •  
  • 0

IMF

The International Monetary Fund (IMF) disclosed a cyber incident on Friday after unknown attackers breached 11 IMF email accounts earlier this year.

This international financial institution, funded by 190 member countries, is also a major United Nations financial agency headquartered in Washington, D.C.

According to a press release published today, the IMF detected the incident in February and is now conducting an investigation to assess the attack's impact.

So far, the IMF has found no evidence that the attackers gained access to other systems or resources outside of the breached email accounts.

"The International Monetary Fund (IMF) recently experienced a cyber incident, which was detected on February 16, 2024. A subsequent investigation, with the assistance of independent cybersecurity experts, determined the nature of the breach, and remediation actions were taken," the IMF said.

"The investigation determined that eleven (11) IMF email accounts were compromised. The impacted email accounts were re-secured. We have no indication of further compromise beyond these email accounts at this point in time. The investigation into this incident is continuing."

While the IMF didn't provide other details regarding the breach, the organization confirmed that it uses the Microsoft 365 cloud-based email platform.

"We can disclose that 11 IMF email accounts were compromised. They have since been re-secured. For security reasons, we cannot disclose further details," an IMF spokesperson told BleepingComputer.

"Yes, we can confirm, IMF does use Microsoft 365 email. Based on our investigative findings to date, this incident does not appear to be part of Microsoft targeting."

Redmond revealed in January that the Midnight Blizzard Russian hacking group tied to the Russian Foreign Intelligence Service (SVR) stole Microsoft corporate emails in a month-long breach after compromising Exchange Online accounts in a password spray attack to access a legacy non-production test tenant environment.

Days later, Hewlett Packard Enterprise (HPE) also disclosed that the Russian hackers had gained unauthorized access to some of its Microsoft Office 365 email accounts and exfiltrated data since May 2023.

It is unclear whether these incidents are connected to the security breach that led to the breach of IMF's email accounts.

The IMF was also hacked in 2011 in an incident described as a "a very major breach" by an official, which forced the World Bank to sever connections between the two organizations' networks as a precaution.

Update March 15, 16:11 EDT: Added IMF statement.

 
البحث
الأقسام
إقرأ المزيد
FBI warns of gift card fraud ring targeting retail companies
May 8, 2024   01:25 PM   0 Image: Midjourney The FBI warned...
بواسطة AFFA 2024-05-08 19:51:49 0 6
Ransomware payments drop to record low of 28% in Q1 2024
April 21, 2024   10:21 AM   0 Ransomware actors have had a rough...
بواسطة AFFA 2024-04-21 19:36:53 0 43
Microsoft pulls fix for Outlook bug behind ICS security alerts
April 23, 2024   05:50 PM   0 Microsoft has rolled back a fix for...
بواسطة AFFA 2024-04-24 17:44:34 0 33
Windows 11 tips and tricks
Windows 11 comes with built-in capabilities that make your life easier. Learn how to use...
بواسطة AFFA 2024-03-11 17:04:55 0 102
Opera sees big jump in EU users on iOS, Android after DMA update
March 23, 2024   12:59 PM   0 Opera has reported a substantial...
بواسطة AFFA 2024-03-24 16:46:09 0 61